Active Directory assessment · service · fixed price per assessment
You know which routes an attacker could take through your Windows network
And in which order to close them. secctl assesses your Active Directory with 51 checks, mapped to MITRE ATT&CK. You get a report with the findings ranked by risk and, for each one, what to do about it, plus a retest within 90 days. We only test with your written permission and within a scope we agree on together.
From €2,950 per assessment, including the debrief and the retest. No quote needed.
- 51 checkson the configuration of your Active Directory
- MITRE ATT&CKthe technique and the fix for each finding
- Retest within 90 daysso you see what has been fixed
- Fixed priceper assessment, including intake and debrief
How an assessment runs
Six steps, from intake to retest. You know beforehand what happens, what stays outside the scope and what it costs.
- Intake. In a 30-minute call we settle the size: which domain, how many accounts, remote or on site.
- Scope and permission in writing. You receive a scope form and a permission statement. Someone authorised to sign for your organisation signs. Without a signature the assessment doesn’t start.
- The assessment. The 51 checks run in your network, remotely or on site. What that needs is listed in the scope form.
- The report. A PDF with the findings ranked by risk, the MITRE ATT&CK technique for each finding and what to do to fix it.
- Debrief. One hour online, with the people who will do the fixing.
- Retest. Within 90 days the assessment runs again and you see, per finding, whether it has been fixed.
What you get
A report your administrator can act on straight away and your board understands in one page.
- The findings ranked by risk, so you know where to start.
- The MITRE ATT&CK technique for each finding, so your administrator or supplier knows exactly what it is about.
- For each finding, what to do to fix it.
- The attack paths between systems: which weakness leads to which next one.
- The audit trail of the assessment: every action, including what was refused outside the scope.
- Credentials that surface during the assessment are redacted in the report.
How the assessment stays within the lines
An assessment inside your network takes trust. That is why the rules live in the tool itself, not only in an agreement.
The tool, Enumerate, refuses every action outside the scope you signed. An empty scope means: nothing.
Every action goes into an append-only audit trail that cannot be changed, including the actions that were refused. You get that trail with the report.
Intrusive checks are off by default. They are switched on only if the scope allows it.
Passwords and other credentials that surface during the assessment are redacted by the tool before they reach the report.
For your board
Four short sections you can forward: why now, what the risk is, what it costs and what it delivers.
The reason
Your insurer, a customer or your auditor asks whether your network has been tested. Almost every organisation with Windows workplaces runs on Active Directory: that is where the accounts, the permissions and the passwords live. Mistakes in that setup pile up over the years without anyone noticing.
The risk
An attacker who gets hold of one ordinary account can use those mistakes to work up to control of the whole network. The assessment shows whether that path exists in your organisation and where it starts, so IT can close it before anyone uses it.
The cost
€2,950 for an environment up to 250 accounts, €4,450 up to 1,000 and €6,950 up to 2,500 accounts, excluding VAT. One fixed price per assessment, with the debrief and the retest included. No quote, no hours billed afterwards.
What it delivers
A list of what is wrong, ranked by risk, with what IT does about each item. After the retest you have the evidence that it has been fixed, for your insurer, your customer or your auditor.
What it costs
One fixed price per assessment, by the size of your environment. Excluding VAT, no quote needed.
| Size | Environment | Per assessment |
|---|---|---|
| Small | up to 250 enabled accounts, one domain | €2,950 |
| Medium | 251 to 1,000 enabled accounts, one domain | €4,450 |
| Large | 1,001 to 2,500 accounts, or several domains in one forest | €6,950 |
Included: the intake, the scope form and the permission statement, the assessment itself (remote or on site), the report as a PDF, a one-hour debrief and one retest within 90 days. Fixing the findings is done by your own administrator or supplier; if you prefer on site, we agree the travel costs beforehand.
More than 2,500 accounts, or several forests? Book a call and you get a tailored price.
Frequently asked questions
What IT administrators and boards ask before they commission an assessment.
Is this a penetration test?
It is an assessment of your Active Directory: 51 checks on the configuration and the attack paths, carried out by secctl, with a report and a retest. A full penetration test looks wider, at web applications or staff for example, and takes longer. If you need that breadth, you will hear so in the intake.
What is needed in our network?
We settle that in the intake and it is written in the scope form. So you know beforehand exactly what the assessment touches and what it doesn’t.
Who has to sign?
Someone authorised to sign for your organisation, such as a director or board member. Testing without the network owner’s permission is a criminal offence; that is why the assessment doesn’t start without a signature.
Can the assessment disrupt anything?
The checks mostly read. Intrusive checks are off by default and only go on if the scope says so. Every action is in the audit trail you receive with the report.
What do we do after the report?
Your administrator or supplier works through the findings in the order of the report. Within 90 days the assessment runs again, and you see per finding whether it has been fixed.
A call first, then the scope
In 30 minutes we settle the size together and what the assessment will and won’t touch. Want to see the software first? Try Awareness or RiskCompass for 30 days with your own organisation.